---
id: CVE-2026-93979
title: >-
  A security flaw has been discovered in code-projects Internship Management
  System 1.0
summary: >-
  A security flaw has been discovered in code-projects Internship Management
  System 1.0. This affects an unknown part of the file /employer/login.php.
  Performing a manipulation of the argument Password results in sql injection.
  The attack …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: code-projects
product: Internship Management System
affected:
  - internship_management_system 1.0
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93979'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/zzzxc643/CVE1/blob/main/2026-8-24/vul7.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-93979'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/944592'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407938'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407938/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00263
epssPercentile: 0.18431
ingestedAt: '2026-09-20T11:20:23.391Z'
---

## Overview

A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
